DocumentCode
3259214
Title
Evaluation of Online Resources in Assisting Phishing Detection
Author
Bian, Kaigui ; Park, Jung-Min ; Hsiao, Michael S. ; Bélanger, France ; Hiller, Janine
Author_Institution
Dept. of Electr. & Comput. Eng., Virginia Tech, Blacksburg, VA, USA
fYear
2009
fDate
20-24 July 2009
Firstpage
30
Lastpage
36
Abstract
Phishing is an attempt to fraudulently acquire userspsila sensitive information, such as passwords or financial information, by masquerading as a trustworthy entity in online transactions. Recently, a number of researchers have proposed using external online resources like the Google Page Rank system to assist phishing detection. The advantage of such an approach is that the detection capability will gradually evolve and improve as the online resources become more sophisticated and manipulation-resistant. In this paper, we evaluate the effectiveness of three popular online resources in detecting phishing sites-viz, Google PageRank system, Yahoo! Inlink data, and Yahoo! directory service. Our results indicate that these online resources can be used to increase the accuracy of phishing site detection when used in conjunction with existing phishing countermeasures. The proposed approach involves examining the following three attributes of a target site (site being examined): (1) the credibility of the target sitepsilas hosting domain, (2) the credibility of in-neighbor sites that link to the hosting domain, and (3) the correlation between the target sitepsilas web category and its hosting domainpsilas web category. The aforementioned online resources by themselves are insufficient to address the phishing attack problem. We provide discussions on how each of those resources may be integrated with existing phishing detection techniques to provide a more effective solution.
Keywords
Web sites; computer crime; search engines; Google PageRank system; Web-based information theft; Yahoo! Inlink data; Yahoo! directory service; external online resources; hosting domain Web category; online resources evaluation; online transactions; phishing countermeasures; phishing site detection; target site Web category; user sensitive information; Application software; Finance; Information systems; Insurance; Internet; Uniform resource locators; World Wide Web;
fLanguage
English
Publisher
ieee
Conference_Titel
Applications and the Internet, 2009. SAINT '09. Ninth Annual International Symposium on
Conference_Location
Bellevue, WA
Print_ISBN
978-1-4244-4776-3
Electronic_ISBN
978-0-7695-3700-9
Type
conf
DOI
10.1109/SAINT.2009.14
Filename
5230664
Link To Document